1. Introduction
This policy covers the ReadLoud app for iOS and the web, made by Red Star Labs. It explains what happens to your data when you use it. The short version: ReadLoud keeps your library and reading audio on your device, has no advertising, and does not sell personal data. Optional AI study tools send only the material you choose for processing. The web app uses email sign-in for subscriptions; iOS uses a pseudonymous App Store entitlement. We also use a pseudonymous installation identifier and document fingerprints to enforce the three-reading free allowance.
Our website (redstarlabs.co) has its own privacy policy; this one is specifically about the app.
2. What stays on your device
- Your library. Documents you import — pasted text, PDFs, scans — are stored only in the app's local storage on your device. They are never uploaded to us for reading aloud.
- Your settings. Reading speed, voice choice, and similar preferences are stored on your device.
- Your voice audio. The natural voice is generated on your device. When the neural voice files are needed, the app downloads the Kokoro voice model (about 90 MB) and selected voice data directly from Hugging Face and caches them on your device. Hugging Face receives ordinary network information, such as your IP address and device or browser information, to deliver those files under its privacy policy, but it does not receive the text you listen to. Speech is synthesised entirely on-device, and downloaded voice files remain cached until the app or its stored data is removed or the device clears them.
Deleting the iOS app deletes its local content. If you use ReadLoud on the web, clearing ReadLoud's site data in your browser deletes its local content there. We can't recover this material, because we never had it.
3. What is sent to a server, and why
ReadLoud's optional study features — Generate, Tutor, Scan, and References — need AI processing that can't run on a phone. When you use one of them, the text or image you submit is sent over an encrypted connection to our server, which passes it to Anthropic's Claude API to produce your result (study notes, an answer, extracted text, or reference details).
- Only the content you actively submit is sent — never your library, settings, or anything else.
- Our server uses it solely to produce your result and does not persist the submitted text, images, or generated result. We do not build profiles from it, use it for advertising, or sell it.
- Our backend is hosted by Netlify, which acts as an infrastructure service provider. Netlify may process ordinary request metadata, including an IP address, user-agent, URL, and request timing, to deliver, monitor, and secure the service under its privacy statement. This hosting-layer processing is separate from ReadLoud's application logs. Under our current hosting configuration, request-level operational metadata may be available for up to 30 days; the actual period depends on the hosting and observability settings in effect and may be shorter.
- Anthropic processes it as our service provider. Under Anthropic's standard API policy, API inputs and outputs are automatically deleted from its backend within 30 days. Anthropic may retain some material for longer when it is flagged for usage-policy enforcement (including inputs and outputs for up to two years), where the law requires it, or where a different retention agreement applies. API inputs and outputs are not used to train Anthropic's models by default. See Anthropic's API retention explanation and privacy policy.
- We do not attach payment details to the material. A study request is associated temporarily with either a pseudonymous subscription identifier or a free-reading document fingerprint so we can confirm access, apply fair-use limits, and prevent abuse. We do not retain the document text or images in those records.
4. Subscription and service-security data
ReadLoud does not require an account for local reading. Web customers use an email magic link to sign in and manage a Stripe subscription; the iOS app sends Apple's signed StoreKit transaction proof to our server. Our server stores only the minimum service data needed to operate the free allowance and Plus:
- for web sign-in, a normalized email address and short-lived sign-in token, followed by a random session token stored only as a one-way hash;
- a one-way pseudonymous account or subscription identifier, the product, subscription status, and expiry date;
- a one-way pseudonymous installation identifier and SHA-256 fingerprints of up to three free documents; the fingerprint is derived from the document text but does not contain the text itself;
- aggregate request and usage totals used for rate limits and monthly fair-use quotas; and
- Apple and Stripe event identifiers used to prevent the same renewal, cancellation, or refund notice being processed twice.
These records are stored for us by Upstash in its managed Redis service under its privacy policy. Upstash acts as an infrastructure service provider; it does not receive the study text, scans, questions, or generated answers that ReadLoud sends to Anthropic. Subscription and free-reading records expire no later than 400 days after their most recent relevant activity. Request counters expire automatically: minute counters within two minutes, daily quota counters shortly after the end of the applicable UTC day, and monthly quota counters shortly after the end of the applicable UTC month. Completed billing event identifiers are kept for 30 days to prevent duplicate processing, then expire automatically.
We process an IP address transiently in the ReadLoud application to enforce security and rate limits. Our application immediately derives a one-way, pseudonymous network identifier from it and keeps that identifier for no more than two minutes. It is used only to recognise unusually rapid requests, not for location, advertising, analytics, or tracking. We do not put document text, scans, questions, transaction proofs, raw IP addresses, or payment details in ReadLoud's application logs. As described above, Netlify may separately process request metadata in its hosting-layer logs.
5. What we don't do
- No account is required for local reading. Email sign-in is required only for web subscription billing and account management.
- No analytics or tracking SDKs in the app.
- No advertising, and no third-party ad networks.
- No sale of personal data and no sharing for advertising. Data is disclosed only to the service providers described in this policy when needed to provide ReadLoud or respond to you.
6. Purchases
Payment is handled by Apple through the App Store on iOS and by Stripe on the web. We never see or store your card number or other payment details. These providers give us customer or transaction identifiers and subscription-status information so we can unlock Plus, restore access, apply usage limits, and stop access after expiry or refund. See Apple's privacy policy and Stripe's privacy policy.
7. Children's privacy
ReadLoud is not directed at children under 13, and we do not knowingly collect personal information from them. Your content remains stored on your device except when you choose an online study feature.
8. Your rights
Depending on where you live (for example under UK GDPR), you have rights over your personal data, including access, correction, and deletion. Because your library lives on your device and our own server doesn't retain submitted study content, most local content-related rights can be exercised by deleting content or the app. Anthropic's standard API retention described above still applies to material processed by its service. For questions or requests concerning a pseudonymous subscription or usage record, email us and we'll explain what proof is needed to locate it without collecting unnecessary identity data. You may also ask us to delete support correspondence, subject to any limited retention required for legal obligations, dispute resolution, or service security.
9. Changes to this policy
If our practices change, we'll update this page and the date at the top. Material changes will be flagged in the app's update notes.
10. Contact
Questions about privacy in ReadLoud: redstarlabs777@hotmail.com. For product help, see ReadLoud Support.
If you email us, our Microsoft-hosted mailbox processes your sender address, the name associated with your email account, message, attachments, and ordinary email headers. We use that information only to answer your request, troubleshoot the service, and protect against abuse. We retain support correspondence while the issue is open and for reasonable follow-up, then delete it when it is no longer needed, unless we must keep a limited record for law, dispute resolution, or security. You can request earlier deletion by emailing the same address. Please do not send document contents, passwords, payment-card details, or signed App Store transaction tokens in a support message.
In plain English: your library, settings, and generated reading audio stay on your device. Hugging Face delivers the downloadable voice files, but it does not receive the text you listen to. If you use a study feature, the material you chose goes securely through our server to Anthropic. Our server does not persist it; Anthropic normally deletes API inputs and outputs within 30 days, subject to the exceptions above. Upstash holds time-limited free-reading, sign-in, subscription, quota, and duplicate-event records. Web subscription billing uses Stripe; iOS billing uses Apple. No ads, no data sales.